57.056 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.056 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2015-2062 | HIGH 7.2 | huge-it huge-it_slider Multiple SQL injection vulnerabilities in the Huge-IT Slider (slider-image) plugin before 2.7.0 for WordPress allow remote administrators to execute arbitrary SQL commands via the removeslide parameter in a popup_posts or edit_cat action in the sliders_huge_it | 2,4% | — |
| CVE-2017-9790 | HIGH 7.5 | apache mesos When handling a libprocess message wrapped in an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.0-dev crashes if the request path is empty, because the parser assumes the request path always starts with ' | 2,4% | — |
| CVE-2014-2106 | HIGH 7.8 | cisco ios Cisco IOS 15.3M before 15.3(3)M2 and IOS XE 3.10.xS before 3.10.2S allow remote attackers to cause a denial of service (device reload) via crafted SIP messages, aka Bug ID CSCug45898. | 2,4% | — |
| CVE-2023-36776 | HIGH 7.0 | microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability | 2,4% | — |
| CVE-2021-36372 | CRIT 9.8 | apache ozone In Apache Ozone versions prior to 1.2.0, Initially generated block tokens are persisted to the metadata database and can be retrieved with authenticated users with permission to the key. Authenticated users may use them even after access is revoked. | 2,4% | — |
| CVE-2021-40114 | MED 6.8 | cisco secure_firewall_management_center Multiple Cisco products are affected by a vulnerability in the way the Snort detection engine processes ICMP traffic that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is d | 2,4% | — |
| CVE-2020-1066 | HIGH 7.8 | microsoft .net_framework An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level. To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program. The updat | 2,4% | — |
| CVE-2019-17657 | HIGH 7.5 | fortinet fortianalyzer An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager below 6.2.3 and FortiAP-S/W2 below 6.2.2 may allow an attacker to cause admin webUI denial of service (DoS) via ha | 2,4% | — |
| CVE-2014-4064 | MED 4.9 | microsoft windows_7 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly handle use of the paged kernel pool for allocation o | 2,4% | — |
| CVE-2019-1840 | HIGH 8.6 | cisco prime_network_registrar A vulnerability in the DHCPv6 input packet processor of Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to restart the server and cause a denial of service (DoS) condition on the affected system. The vulnerability is due to incomp | 2,4% | — |
| CVE-2015-3108 | MED 5.0 | adobe air Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and | 2,4% | — |
| CVE-2023-2317 | HIGH 8.6 | typora typora DOM-based XSS in updater/update.html in Typora before 1.6.7 on Windows and Linux allows a crafted markdown file to run arbitrary JavaScript code in the context of Typora main window via loading typora://app/typemark/updater/update.html in <embed> tag. This vul | 2,4% | — |
| CVE-2020-1528 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Radio Manager API improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted appl | 2,4% | — |
| CVE-2007-5337 | MED 4.3 | gnome gnome-vfs Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome-vfs support, might allow remote attackers to read arbitrary files on SSH/sftp servers that accept key authentication by creating a web page on the target server | 2,4% | — |
| CVE-2021-26987 | CRIT 9.8 | netapp element_plug-in_for_vcenter_server Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are susceptible to a vulnerability which when successfully exploited could lead to Remote Code Execution. All versions of Element Plug-in for vCe | 2,4% | — |
| CVE-2019-0951 | MED 5.4 | microsoft sharepoint_foundation A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0949, CVE-2019- | 2,4% | — |
| CVE-2022-26940 | MED 6.5 | microsoft remote_desktop_client Remote Desktop Protocol Client Information Disclosure Vulnerability | 2,4% | — |
| CVE-2022-22015 | MED 6.5 | microsoft remote_desktop_client Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | 2,4% | — |
| CVE-2022-23280 | MED 5.3 | microsoft outlook_2016 Microsoft Outlook for Mac Security Feature Bypass Vulnerability | 2,4% | — |
| CVE-2015-6428 | MED 5.0 | cisco dpq3925_8x4_docsis_3.0_wireless_residential_gateway_with_embedded_digital_voice_adapter Cisco DPQ3925 devices with EDVA r1 Base allow remote attackers to obtain sensitive information via a crafted HTTP request, aka Bug ID CSCuv03958. | 2,4% | — |
| CVE-2010-0730 | LOW 2.6 | redhat enterprise_linux The MMIO instruction decoder in the Xen hypervisor in the Linux kernel 2.6.18 in Red Hat Enterprise Linux (RHEL) 5 allows guest OS users to cause a denial of service (32-bit guest OS crash) via vectors that trigger an unspecified instruction emulation. | 2,4% | — |
| CVE-2001-1056 | HIGH 7.5 | linux linux_kernel IRC DCC helper in the ip_masq_irc IP masquerading module 2.2 allows remote attackers to bypass intended firewall restrictions by causing the target system to send a "DCC SEND" request to a malicious server which listens on port 6667, which may cause the module | 2,4% | — |
| CVE-1999-0376 | MED 4.6 | microsoft windows_nt Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs. | 2,4% | — |
| CVE-2024-38230 | MED 6.5 | microsoft windows_server_2012 Windows Standards-Based Storage Management Service Denial of Service Vulnerability | 2,4% | — |
| CVE-2021-35994 | HIGH 7.8 | adobe after_effects Adobe After Effects version 18.2.1 (and earlier) is affected by an out-of-bounds Write vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the | 2,4% | — |